Tailscale MCP server for managing your tailnet from AI assistants
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
One click adds this to your local Yaw MCP config so it's available in every Yaw Terminal session. Or install manually below.
Ask your agent questions about your tailnet and have it act on the answers. 97 admin-API tools + 6 optional local-CLI diagnostics + 1 always-on catalog tool + 4 resources spanning the Tailscale v2 API β devices, ACLs, DNS, keys and trust credentials, users, invites, webhooks, log streaming, posture, services, and organization tailnets. Backed by 1900+ unit tests and an opt-in live-tailnet integration suite.
Built and maintained by Yaw Labs.
You could curl the Tailscale API. The point isn't replacing curl β it's letting an agent compose multi-endpoint workflows in one turn without writing a script:
lastSeen (online devices carry none), filters by keyExpiryDisabled, returns a table. Three endpoints, one question.tag:mobile reach tag:dashboard but not tag:db, preserving my comments" β reads the current HuJSON, proposes a minimal diff, validates it against the API, returns the diff for you to apply.devices:core:read and dns:read" β creates a trust credential via tailscale_create_key with keyType=client, returns the credentials once (save them immediately).A curl can do each step. The agent composes them. That's where the lift is, and that's what the tool surface is designed for β every read endpoint is first-class so the agent can synthesize, and every write endpoint is tagged destructiveHint or idempotentHint so your MCP client can gate mutations the way you configured it.
If all you need is one endpoint in a CI job, use curl β we even have a CLI subcommand for the common ACL-from-git case. The MCP is for the interactive, exploratory, "I don't know what I need yet" work.
tailscale CLI?Reasonable question. Both have their place. Where this MCP is better:
tailscale CLI is scoped to the node it runs on. Admin concerns β ACLs, users, invites, webhooks, log streaming, posture integrations, auth keys, OAuth clients, and federated identities β live in the v2 HTTP API. You'd be shelling out to curl anyway.tailscale status --json | jq pipelines that break when the schema evolves.npx β nobody rewrites a skill's instructions when Tailscale adds an endpoint.readOnlyHint / destructiveHint / idempotentHint so clients can skip confirmation on reads and require it on mutations. A skill that shells out to the CLI can't express that.RUN_INTEGRATION_TESTS=1 + a tailnet API key) for shape-drift detection. Most skills are short markdown prompts without their own test layer β if the vendor changes output format, nothing catches it for you.If you already have a skill that covers your 10% of Tailscale workflows, great β keep it. The MCP is for the other 90%.
What about Tailscale's own MCP endpoints and skill? As of 2026-09-19 they solve different problems, and nothing here duplicates them. Tailscale's official MCP tools are two alpha built-in connectors inside Aperture: Tailnet, whose Tailnet_provision_node returns a single-use auth key so an agent can join one new node after a person approves it, and Tailscale SSH, whose TailnetSSH_list_machines and TailnetSSH_run_command discover SSH-enabled machines and run one command on one of them. They require Aperture. tailscale/tailscale-skill is an alpha, knowledge-only skill β reference material that teaches an agent to curl the v2 API, with no server of its own. Neither exposes the admin API as typed tools, so the overlap with this server is close to nil. Nor can Aperture front this one today: this server speaks stdio, and Aperture proxies only URL-addressable Streamable-HTTP or SSE servers. Both of those products are alpha, so treat the date on this paragraph as its expiry.
Fair critique from Reddit: a new repo claiming "actively maintained" with no visible tests is worth exactly zero trust. Here's what's actually verifiable:
node --test) covering every tool's input validation, API shape, and error handling. Run npm test to see them pass locally.release.sh: lint + test + bump + tag + push + npm publish + MCP Registry publish, all from the workstation. No CI workflow to babysit.Issues and PRs are triaged. File one if something is off β github.com/YawLabs/tailscale-mcp/issues.
1. Set your API key
Get an API key from Tailscale Admin Console > Settings > Keys and set it where your MCP client will see it. The .mcp.json env block in step 2 works identically on every platform and is the option to prefer; to export it from a shell profile instead (~/.bashrc, ~/.zshrc, ~/.config/fish/config.fish):
macOS / Linux / WSL (bash, zsh):
fish:
Windows (PowerShell 5.1 and 7) β [Environment]::SetEnvironmentVariable persists it for the user, where $env: alone lasts only for the session:
2. Create .mcp.json in your project root
macOS / Linux / WSL:
Windows:
Why the extra step on Windows? On Windows,
npxis a.cmdfile, and Node 20+ refuses to spawn.cmdfiles directly. Wrapping withcmd /cis the standard workaround.
3. Restart and approve
Restart Claude Code (or your MCP client) and approve the Tailscale MCP server when prompted.
That's it. Now ask your agent:
"List my Tailscale devices that haven't been seen in the last 7 days"
"Summarize every ACL change in the audit log from yesterday"
"Draft an ACL rule that lets
tag:cireachtag:registryon port 5000 only"
97 tools is a lot. If you've already got a dozen MCP servers and your client is feeling heavy, trim what this one exposes. Three knobs, combinable:
The
envblocks below show only the variable under discussion. Your credentials come from the environment, as set in Quick start β keep them in your shell profile rather than in the client's JSON config, which is world-readable on most systems and easy to commit by accident.
TAILSCALE_PROFILE (preset, easiest)minimal (20 tools) β status, devices, audit. Observe the tailnet, read the audit log.core (52 tools) β adds acl, dns, keys, users. The day-to-day admin surface.full (97 tools, default) β everything. Same as omitting the env var.TAILSCALE_TOOLS (explicit group list)Comma-separated group names. Overrides TAILSCALE_PROFILE when both are set β use this when the presets aren't quite right.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/tailscale-mcp-server-2)<a href="https://allmcps.com/mcp/tailscale-mcp-server-2"><img src="https://allmcps.com/api/badge/tailscale-mcp-server-2?style=directory" alt="Tailscale MCP Server on AllMCPs" /></a>